← Insights

Same pattern. Different contract.

In a standard system an event is a notification. Consume it, react, move on.

In a clinical SaMD an event is a clinical state transition. It has to be traceable, auditable and safe to replay.

  • Broker choice is a regulatory decision. Kafka, RabbitMQ, EventBridge: every broker is SOUP, version-pinned and risk-justified in the DHF.
  • Event schemas are software interfaces. The producer-consumer contract is versioned and change-controlled, and a breaking schema means a full impact analysis.
  • Idempotency and ordering are risk controls. The wrong order means the wrong clinical state. Idempotency keys and dead letter queues belong in the RMF, not just in code.
  • Correlation ID across the full chain. OpenTelemetry or CloudWatch traces show what was produced, consumed, retried and dead-lettered. That is your CAPA trail.
  • Failure modes are hazard scenarios. Broker down, consumer fails, duplicate delivery. Circuit breakers and DLQs are the risk controls.

Failure isolation, auditable state, full replay. The architecture is not the problem. Treating it like any other system is.

Seen this differently?

Questions, corrections and counterexamples are welcome.

Related

Keep reading